Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clipboard or terminal scrollback mnemonic vulnerability #32

Closed
valefar-on-discord opened this issue May 4, 2024 · 2 comments · Fixed by #158
Closed

Clipboard or terminal scrollback mnemonic vulnerability #32

valefar-on-discord opened this issue May 4, 2024 · 2 comments · Fixed by #158

Comments

@valefar-on-discord
Copy link
Collaborator

valefar-on-discord commented May 4, 2024

Forward from

The 2020 Audit of staking-deposit-cli mentioned a task to properly clear the terminal buffer and clipboard to prevent the possibility of leaking the mnemonic. This was investigated by Carl and he has concerns around cross-platform solutions.

Ultimately it may not be possible to resolve this for every usecase but something that should be investigated as is a likely output from any future audit.

@remyroy
Copy link
Member

remyroy commented Jun 3, 2024

Using of the the flag where you input a mnemonic or a password from the CLI could also be an interesting case where most CLI or shells have a feature to store the history of commands in a file somewhere. I'm not sure we can do a lot beside just warning about it.

@remyroy
Copy link
Member

remyroy commented Jun 3, 2024

My last comment is probably more related to #33

@remyroy remyroy linked a pull request Sep 16, 2024 that will close this issue
3 tasks
@remyroy remyroy removed a link to a pull request Sep 16, 2024
3 tasks
@yorickdowne yorickdowne mentioned this issue Sep 17, 2024
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants